Vulnerabilities > CVE-2021-39356 - Unspecified vulnerability in Content Staging Project Content Staging
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via several parameters that are echo'd out via the ~/templates/settings.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.0.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
Vulnerable Configurations
References
- https://github.com/BigTiger2020/word-press/blob/main/Content%20Staging.md
- https://github.com/BigTiger2020/word-press/blob/main/Content%20Staging.md
- https://plugins.trac.wordpress.org/browser/content-staging/trunk/templates/settings.php
- https://plugins.trac.wordpress.org/browser/content-staging/trunk/templates/settings.php
- https://wordfence.com/vulnerability-advisories/#CVE-2021-39356
- https://wordfence.com/vulnerability-advisories/#CVE-2021-39356